IP Library Granted Patent US 11,250,423
Granted Patent B2
US 11,250,423 · App. 16/547,855 · Granted Feb 15, 2022

Encapsulated security tokens for electronic transactions

Inventor: Mark A. Heyner (Golden, CO)
Assignee: INSTITUTIONAL CASH DISTRIBUTORS TECHNOLOGY, LLC
G06Q20/3829G06F21/60G06F21/602G06F21/64G06Q20/385G06Q20/3823G06Q20/3825H04L9/321H04L9/3234H04L9/3247H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,250,423
App. No.
16/547,855
Granted
Feb 15, 2022
Kind
B2
Abstract

Functional data for use in one or more digital transactions are secured by using an encapsulated security token (EST). In certain embodiments, the EST is created by encapsulating digital data including the functional data using at least two cryptographic systems of two parties. The encapsulation and subsequent de-encapsulation can utilize cryptographic systems of the parties that involve a private key for signing and decryption and a public key for encryption and signature verification. If constructed carefully over a series of rigorous events, the resulting EST can be practically impossible to counterfeit. In addition, a propagation of rights can be tracked for auditing and rights can be easily terminated or modified.

Claims (19)

1. A method for use in propagating authority to use functional data in connection with a digital transaction, comprising the steps of:

receiving first digital data including at least functional data;

adding to said first digital data at least first authorization data to identify a first authorized party and originator credential data to identify an originator of the functional data;

generating a first encapsulated security token by encapsulating at least (i) said first authorization data and (ii) said originator credential data using at least a first cryptographic system including a digital signature of the originator and an originator signature verification;

generating a twice-encapsulated security token by encapsulating at least (i) said first encapsulated security token and (ii) a second authorization data to identify a second authorized party using at least a second cryptographic system including a digital signature of the first authorized party and a first authorized party signature verification;

propagating said twice-encapsulated security token to said second authorized party;

receiving a proposed digital transaction including proposed authorization data of said second authorized party;

verifying authorization of said second authorized party for the proposed digital transaction by (i) de-encapsulating said twice-encapsulated security token using at least the originator signature verification and the first authorized party signature verification to obtain extracted authorization data including at least the first authorization data and the second authorization data and (ii) comparing the extracted authorization data with the proposed authorization data; and

responsive to verifying authorization of said second authorized party for the proposed digital transaction, using the functional data for the proposed digital transaction.

2. A system for use in propagating authority to use functional data in connection with a digital transaction, comprising:

one or more processors operative for:

receiving first digital data including at least functional data;

adding to said first digital data at least first authorization data to identify a first authorized party and originator credential data to identify an originator of the functional data;

generating a first encapsulated security token by encapsulating at least (i) said first authorization data and (ii) said originator credential data using at least a first cryptographic system including a digital signature of the originator and an originator signature verification;

generating a twice-encapsulated security token by encapsulating at least (i) said first encapsulated security token and (ii) a second authorization data to identify a second authorized party using at least a second cryptographic system including a digital signature of the first authorized party and a first authorized party signature verification;

propagating said encapsulated security token to said authorized party;

receiving a proposed digital transaction including proposed authorization data of said second authorized party;

verifying authorization of said second authorized party for the proposed digital transaction by (i) de-encapsulating said twice-encapsulated security token using at least the originator signature verification and the first authorized party signature verification to obtain extracted authorization data including at least the first authorization data and the second authorization data and (ii) comparing the extracted authorization data with the proposed authorization data; and

responsive to verifying authorization of said second authorized party for the proposed digital transaction, using the functional data for the proposed digital transaction.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2024
From: INSTITUTIONAL CASH DISTRIBUTORS TECHNOLOGY, LLC
To: TRADEWEB MARKETS LLC
Reel/Frame 068164/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2019
From: HEYNER, MARK A.
To: INSTITUTIONAL CASH DISTRIBUTORS TECHNOLOGY, LLC
Reel/Frame 050131/0769 →
Continuity (5)
Division 14019989 · Sep 6, 2013
Continuation In Part 13888322 · May 6, 2013
Continuation In Part 13888233 · May 6, 2013
Provisional Application 61643195 · May 4, 2012
Related Publication 20190378130A1 · Dec 12, 2019
Cited By (5)
US 12,190,314 US 12,321,469 US 12,430,639 US 12,483,538 US 12,718,229